New attacks against unfinished installations of WordPress aim to give attackers admin access and the opportunity to run PHP code.

The campaign, which was revealed by security specialist Wordfence, peaked during May and June when attackers targeted recently installed, but not configured, instances WordPress, SecurityWeek reported. Outsiders can use a successful attack to take over the new WordPress website and then potentially gain access to the entire hosting account.

Accessing WordPress Sites

According to the SecurityWeek article, many WordPress users install the platform by either unzipping the archive into a directory on their hosting account or by using a one-click installer from a hosting provider. But the process remains incomplete until a user creates a configuration file, and those who fail to complete installation leave themselves open to attack. In a blog post for Wordfence, chief executive Mark Maunder said his firm noticed that these high-level attackers started targeting unfinished WordPress installations.

Attackers scan for the setup URL and identify new instances of WordPress in which a user has uploaded the WordPress content management system but not completed the configuration. Such sites are open to outside connections, making it possible for external parties to access and complete the installation on the user’s behalf.

Malicious actors who discover an unfinished install can click through language selection and an introductory message before entering their own database-server information. WordPress then confirms that it can communicate with the database, allowing the outsider to complete installation, create an admin account and sign in to WordPress on the victim’s server.

The Dangers of PHP Code Execution

An attacker with admin access to a WordPress website can execute any PHP code and can undertake a range of malicious activities. Wordfence said a common action is to install a malicious shell in a hosting account. Such errant activity allows an attacker to access all files, websites and even databases on a WordPress account.

Wordfence suggested that there are several ways to complete this task, such as launching a theme and inserting PHP code, or creating and uploading a custom plug-in.

If news of the PHP code threat is not bad enough, a Wordfence report warned that the number of daily complex attacks against WordPress rose to 7.2 million in June 2017, up 32 percent from May. The average number of daily brute-force attacks increased by 36 percent month to month, with a peak level at more than 41 million.

Responding Effectively

Security experts suggested that incomplete WordPress installations remain a threat. One simple mitigation step is to complete configuration during the installation process. In his blog post for Wordfence, Maunder suggested that website admins could scan their hosting accounts for incomplete installations. Monitoring and auditing can also provide a further level of protection, he said.

Site owners should take note of the ever-growing threat from both unfinished WordPress installations and PHP code violations. They should work to fill potential security holes by completing configuration exercises, and by drawing on monitoring and auditing best practices.

More from

The Evolution of Antivirus Software to Face Modern Threats

Over the years, endpoint security has evolved from primitive antivirus software to more sophisticated next-generation platforms employing advanced technology and better endpoint detection and response.  Because of the increased threat that modern cyberattacks pose, experts are exploring more elegant ways of keeping data safe from threats.Signature-Based Antivirus SoftwareSignature-based detection is the use of footprints to identify malware. All programs, applications, software and files have a digital footprint. Buried within their code, these digital footprints or signatures are unique to the respective…

How Do Threat Hunters Keep Organizations Safe?

Neil Wyler started his job amid an ongoing cyberattack. As a threat hunter, he helped his client discover that millions of records had been stolen over four months. Even though his client used sophisticated tools, its threat-hunting technology did not detect the attack because the transactions looked normal. But with Wyler’s expertise, he was able to realize that data was leaving the environment as well as entering the system. His efforts saved the company from suffering even more damage and…

The White House on Quantum Encryption and IoT Labels

A recent White House Fact Sheet outlined the current and future U.S. cybersecurity priorities. While most of the topics covered were in line with expectations, others drew more attention. The emphasis on critical infrastructure protection is clearly a top national priority. However, the plan is to create a labeling system for IoT devices, identifying the ones with the highest cybersecurity standards. Few expected that news. The topic of quantum-resistant encryption reveals that such concerns may become a reality sooner than…

Contain Breaches and Gain Visibility With Microsegmentation

Organizations must grapple with challenges from various market forces. Digital transformation, cloud adoption, hybrid work environments and geopolitical and economic challenges all have a part to play. These forces have especially manifested in more significant security threats to expanding IT attack surfaces. Breach containment is essential, and zero trust security principles can be applied to curtail attacks across IT environments, minimizing business disruption proactively. Microsegmentation has emerged as a viable solution through its continuous visualization of workload and device communications…